Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit.Agent/gen-tdssw


  • This topic is locked This topic is locked
2 replies to this topic

#1 killbugsdead

killbugsdead

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:35 PM

Posted 10 August 2010 - 09:34 AM

Good morning ladies/gentlemen i am reposting this issue with logs this time sorry for the first post.
I am including the DDS log as well as the combofix logs. The GMER software keeps crashing the computer. last vnight it ran untill i got to the point where it says:

You will see the main GMER window. if it gives you a warning about rootkit acivity and wants afull scan say no.

at that point the machine crashes but I can see

service hidden boot ekpiopi
service hidden boot quepv

These are the files that keep copmming back as trojans and I can't seem to remove them

Anyway log files DDS.txt

DDS (Ver_10-03-17.01) - NTFSx86
Run by dan at 20:17:17.14 on Mon 08/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1552 [GMT -7:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\dan\Desktop\dds.scr

============== Pseudo HJT Report ===============

uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0360.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0360.0\npwinext.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [GFI Backup 2009 - Home Edition] "c:\progra~1\gfi\gfibac~1\GFIAgent.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1276318193953
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dan\applic~1\mozilla\firefox\profiles\0kxie2lv.default\
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [2010-1-27 51840]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2010-1-27 143256]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2010-1-27 24971]
S0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [2010-1-27 85888]
S0 mv614x;mv614x;c:\windows\system32\drivers\mv614x.sys [2010-1-27 61184]
S0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [2010-1-27 89610]
S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [2010-1-27 45568]
S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2010-1-27 77056]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys [2010-5-7 1691480]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys --> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-6-15 30192]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys --> c:\windows\system32\drivers\ivusb.sys [?]

=============== Created Last 30 ================

2010-08-10 02:07:07 0 d-----w- C:\aaa
2010-08-10 01:05:54 0 ----a-w- c:\documents and settings\dan\defogger_reenable
2010-08-10 00:06:16 0 d-----w- c:\docume~1\dan\applic~1\SUPERAntiSpyware.com
2010-08-10 00:06:16 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-08-10 00:06:10 0 d-----w- c:\program files\SUPERAntiSpyware
2010-08-09 23:07:10 0 d-sh--w- c:\documents and settings\dan\IECompatCache
2010-08-09 22:59:54 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-09 22:58:03 0 dc-h--w- c:\windows\ie8
2010-08-04 23:43:33 0 d-sha-r- C:\cmdcons
2010-08-04 23:42:49 77312 ----a-w- c:\windows\MBR.exe
2010-08-04 23:42:48 98816 ----a-w- c:\windows\sed.exe
2010-08-04 23:42:48 256512 ----a-w- c:\windows\PEV.exe
2010-08-04 23:42:48 161792 ----a-w- c:\windows\SWREG.exe
2010-08-04 23:20:35 0 d-----w- c:\program files\Enigma Software Group
2010-08-04 23:20:11 0 d-----w- c:\windows\95431C66CF9A4913BFFF6050785AFB65.TMP
2010-08-04 23:20:10 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-08-04 19:48:11 0 d-----w- c:\docume~1\dan\applic~1\Western DigitalTemp
2010-08-04 19:44:07 0 d-----w- c:\docume~1\dan\applic~1\Western Digital
2010-08-04 19:40:08 0 d-----w- c:\program files\GFI
2010-08-04 15:06:13 0 d-----w- c:\program files\MSXML 4.0
2010-08-04 14:54:48 0 d-----w- c:\windows\pss
2010-08-04 14:17:55 0 d-----w- c:\program files\AVG
2010-08-04 14:09:08 765952 ----a-w- c:\windows\system32\drivers\quepv.sys
2010-08-04 14:08:42 585472 ----a-w- c:\windows\system32\drivers\ekpiolpi.sys
2010-08-04 13:51:38 0 d-----w- c:\docume~1\alluse~1\applic~1\F-Secure
2010-08-03 20:18:48 120 ----a-w- c:\windows\Fyivale.dat
2010-08-03 20:18:48 0 ----a-w- c:\windows\Cluba.bin
2010-07-27 18:58:07 4199784 ----a-w- c:\windows\system32\cdintf400.dll
2010-07-27 18:31:34 0 d-----w- c:\windows\system32\appmgmt
2010-07-27 18:07:08 0 d-----w- c:\program files\common files\AnswerWorks 5.0

==================== Find3M ====================

2010-08-04 01:37:39 81920 ----a-w- c:\windows\DUMP2d78.tmp
2010-07-17 12:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-14 23:10:34 449 ----a-w- c:\program files\0614201016103400.bat
2010-06-03 02:41:44 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-18 23:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 23:35:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2002-09-11 14:26:52 63730 ----a-w- c:\program files\viewsonicinstruct_xp.pdf
2010-05-08 00:48:30 32768 --sha-w- c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\userdata\index.dat

============= FINISH: 20:17:29.92 ===============

Combofix log:
ComboFix 10-08-04.04 - dan 08/04/2010 16:44:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1366 [GMT -7:00]
Running from: c:\documents and settings\dan\Desktop\dog.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\dan\Local Settings\Application Data\{2AEB4288-F2EC-4B55-B5F7-2851E2914C40}
c:\documents and settings\dan\Local Settings\Application Data\{2AEB4288-F2EC-4B55-B5F7-2851E2914C40}\chrome.manifest
c:\documents and settings\dan\Local Settings\Application Data\{2AEB4288-F2EC-4B55-B5F7-2851E2914C40}\chrome\content\_cfg.js
c:\documents and settings\dan\Local Settings\Application Data\{2AEB4288-F2EC-4B55-B5F7-2851E2914C40}\chrome\content\overlay.xul
c:\documents and settings\dan\Local Settings\Application Data\{2AEB4288-F2EC-4B55-B5F7-2851E2914C40}\install.rdf
c:\windows\system32\Drivers\bfoupqjp.sys
c:\windows\system32\Drivers\luufu.sys
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-07-04 to 2010-08-04 )))))))))))))))))))))))))))))))
.

2010-08-04 23:20 . 2010-08-04 23:20 -------- d-----w- c:\program files\Enigma Software Group
2010-08-04 23:20 . 2010-08-04 23:28 -------- d-----w- c:\windows\95431C66CF9A4913BFFF6050785AFB65.TMP
2010-08-04 23:20 . 2010-08-04 23:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-08-04 21:05 . 2010-08-04 21:05 362752 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-04 19:49 . 2010-08-04 19:49 -------- d-----w- c:\documents and settings\dan\Local Settings\Application Data\WDC
2010-08-04 19:48 . 2010-08-04 19:49 -------- d-----w- c:\documents and settings\dan\Application Data\Western DigitalTemp
2010-08-04 19:44 . 2010-08-04 19:55 -------- d-----w- c:\documents and settings\dan\Application Data\Western Digital
2010-08-04 19:40 . 2010-08-04 19:40 -------- d-----w- c:\program files\GFI
2010-08-04 15:06 . 2010-08-04 15:06 -------- d-----w- c:\program files\MSXML 4.0
2010-08-04 14:17 . 2010-08-04 14:17 -------- d-----w- c:\program files\AVG
2010-08-04 14:17 . 2010-08-04 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-08-04 14:10 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-04 14:10 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-04 14:10 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-04 14:10 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-04 14:10 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-04 14:10 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-04 14:10 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-04 14:10 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-04 14:10 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-04 14:09 . 2010-08-04 23:48 765952 ----a-w- c:\windows\system32\drivers\quepv.sys
2010-08-04 14:08 . 2010-08-04 23:48 585472 ----a-w- c:\windows\system32\drivers\ekpiolpi.sys
2010-08-04 13:51 . 2010-08-04 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-08-04 13:36 . 2010-08-04 13:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-08-03 20:18 . 2010-08-04 19:29 120 ----a-w- c:\windows\Fyivale.dat
2010-08-03 20:18 . 2010-08-04 13:45 0 ----a-w- c:\windows\Cluba.bin
2010-08-03 20:17 . 2010-08-04 13:40 765440 ----a-w- c:\windows\system32\drivers\zcbnd.sys
2010-08-03 20:17 . 2010-08-04 13:40 585472 ----a-w- c:\windows\system32\drivers\vcknph.sys
2010-08-03 20:16 . 2010-08-03 20:16 -------- d-----w- c:\windows\Sun
2010-07-27 18:58 . 2010-07-27 18:58 808448 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191119-19121.dll
2010-07-27 18:58 . 2010-07-27 18:58 239976 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2010-07-27 18:58 . 2010-07-27 18:58 956 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2010-07-27 18:58 . 2010-07-27 18:58 223584 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2010-07-27 18:58 . 2009-11-10 02:37 4199784 ----a-w- c:\windows\system32\cdintf400.dll
2010-07-27 18:07 . 2010-07-27 18:07 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2010-07-27 17:15 . 2010-07-27 17:15 -------- d-----w- C:\aaa
2010-07-27 03:24 . 2010-07-27 03:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-04 23:48 . 2010-06-12 04:28 -------- d-----w- c:\documents and settings\dan\Application Data\Skype
2010-08-04 23:17 . 2010-06-17 03:34 -------- d-----w- c:\documents and settings\dan\Application Data\skypePM
2010-08-04 19:55 . 2010-06-12 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Western Digital
2010-08-04 15:20 . 2010-06-14 23:08 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-04 15:08 . 2010-06-12 04:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-04 14:12 . 2010-06-12 04:28 -------- d-----w- c:\documents and settings\dan\Application Data\mp3rocket
2010-08-04 14:10 . 2010-06-12 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-08-04 14:08 . 2010-08-04 14:08 20 ----a-w- c:\documents and settings\LocalService\Application Data\bawuho.dat
2010-08-04 01:37 . 2010-01-27 08:25 81920 ----a-w- c:\windows\DUMP2d78.tmp
2010-08-03 20:17 . 2010-08-03 20:17 20 ----a-w- c:\documents and settings\NetworkService\Application Data\bawuho.dat
2010-07-27 18:59 . 2010-06-12 04:26 -------- d-----w- c:\program files\Quicken
2010-07-27 18:07 . 2010-05-08 00:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-23 21:06 . 2010-08-03 20:16 195670 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-07-10 14:15 . 2010-06-12 03:09 -------- d-----w- c:\documents and settings\dan\Application Data\CyberLink
2010-07-10 14:13 . 2010-05-08 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2010-06-22 16:09 . 2010-06-12 04:28 -------- d-----w- c:\documents and settings\dan\Application Data\Apple Computer
2010-06-22 16:03 . 2010-06-22 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-22 16:03 . 2010-06-12 04:26 -------- d-----w- c:\program files\iTunes
2010-06-22 16:02 . 2010-06-12 04:26 -------- d-----w- c:\program files\iPod
2010-06-22 16:02 . 2010-06-12 04:26 -------- d-----w- c:\program files\Common Files\Apple
2010-06-22 16:02 . 2010-06-22 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-22 16:02 . 2010-06-12 04:26 -------- d-----w- c:\program files\QuickTime
2010-06-22 16:02 . 2010-06-22 16:02 -------- d-----w- c:\program files\Apple Software Update
2010-06-22 16:01 . 2010-06-22 16:01 -------- d-----w- c:\program files\Bonjour
2010-06-22 16:01 . 2010-06-22 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-06-22 15:54 . 2010-06-22 15:54 -------- d-----w- c:\program files\Audible
2010-06-21 15:18 . 2010-06-21 15:18 61440 ----a-w- c:\documents and settings\dan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5d572c3d-n\decora-sse.dll
2010-06-21 15:18 . 2010-06-21 15:18 503808 ----a-w- c:\documents and settings\dan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1e72466a-n\msvcp71.dll
2010-06-21 15:18 . 2010-06-21 15:18 499712 ----a-w- c:\documents and settings\dan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1e72466a-n\jmc.dll
2010-06-21 15:18 . 2010-06-21 15:18 348160 ----a-w- c:\documents and settings\dan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1e72466a-n\msvcr71.dll
2010-06-21 15:18 . 2010-06-21 15:18 12800 ----a-w- c:\documents and settings\dan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5d572c3d-n\decora-d3d.dll
2010-06-18 15:15 . 2010-06-18 04:43 -------- d-----w- c:\program files\Common Files\Java
2010-06-18 15:15 . 2010-06-18 15:15 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-18 15:15 . 2010-06-18 04:43 -------- d-----w- c:\program files\Java
2010-06-18 04:44 . 2010-06-12 04:26 -------- d-----w- c:\program files\MP3 Rocket
2010-06-17 14:51 . 2010-06-12 04:26 -------- d-----w- c:\program files\Instant Housecall
2010-06-17 03:34 . 2010-06-12 04:26 -------- d-----w- c:\program files\Google
2010-06-17 03:34 . 2010-06-17 03:34 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-06-17 03:32 . 2010-06-17 03:32 -------- d-----w- c:\program files\Common Files\Skype
2010-06-17 03:32 . 2010-06-12 04:26 -------- d-----r- c:\program files\Skype
2010-06-17 03:32 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-06-16 04:36 . 2010-06-16 04:36 -------- d-----w- c:\documents and settings\dan\Application Data\EPSON
2010-06-16 03:01 . 2010-06-16 03:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 23:10 . 2010-05-08 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\Temp
2010-06-14 23:10 . 2010-06-14 23:10 449 ----a-w- c:\program files\0614201016103400.bat
2010-06-14 23:09 . 2010-06-14 23:08 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-06-14 23:09 . 2010-06-14 23:09 -------- d-----w- c:\program files\Microsoft
2010-06-14 23:09 . 2010-06-14 23:09 -------- d-----w- c:\program files\MSN Toolbar
2010-06-14 23:08 . 2010-06-14 23:08 -------- d-----w- c:\program files\MSN Games
2010-06-14 18:06 . 2010-06-14 18:06 -------- d-----w- c:\documents and settings\dan\Application Data\Leader Technologies
2010-06-14 18:03 . 2010-06-14 18:03 -------- d-----w- c:\program files\Common Files\Palo Alto Software
2010-06-14 18:03 . 2010-06-14 18:03 -------- d-----w- c:\program files\Common Files\Intuit
2010-06-14 18:03 . 2010-06-14 18:03 -------- d-----w- c:\documents and settings\dan\Application Data\Intuit
2010-06-14 16:54 . 2010-06-14 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2010-06-14 16:36 . 2010-06-14 16:36 -------- d-----w- c:\documents and settings\dan\Application Data\Leadertech
2010-06-14 16:34 . 2010-06-14 16:25 -------- d-----w- c:\program files\epson
2010-06-14 16:34 . 2010-06-14 16:34 -------- d-----w- c:\program files\LTCM Client
2010-06-14 16:33 . 2010-06-14 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\UDL
2010-06-14 16:33 . 2010-06-14 16:33 -------- d-----w- c:\program files\Epson Software
2010-06-14 16:26 . 2010-06-14 16:26 -------- d-----w- c:\documents and settings\dan\Application Data\InstallShield
2010-06-14 14:31 . 2010-01-27 16:38 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-13 16:41 . 2010-06-13 16:41 -------- d-----w- c:\documents and settings\dan\Application Data\Malwarebytes
2010-06-13 16:41 . 2010-06-13 16:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-13 16:41 . 2010-06-13 16:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-13 04:58 . 2010-06-13 04:58 -------- d-----w- c:\program files\GPLGS
2010-06-13 04:57 . 2010-06-13 04:57 -------- d-----w- c:\program files\Acro Software
2010-06-13 04:56 . 2010-06-12 04:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-12 14:50 . 2010-06-12 03:13 74320 ----a-w- c:\documents and settings\dan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 05:49 . 2010-06-12 05:49 -------- d-----w- c:\program files\Windows Media Connect 2
2010-06-12 05:12 . 2010-06-12 05:12 -------- d-----w- c:\program files\CCleaner
2010-06-12 05:03 . 2010-06-12 04:06 -------- d-----w- c:\program files\Microsoft Works
2010-06-12 04:42 . 2010-06-12 04:26 -------- d-----w- c:\program files\viewsonic
2010-06-12 04:41 . 2010-06-12 04:26 -------- d-----w- c:\program files\Microsoft LifeCam
2010-06-12 04:41 . 2010-06-12 04:26 -------- d-----w- c:\program files\Kyodai Mahjongg 2006
2010-06-12 04:28 . 2010-06-12 04:08 134144 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2010-06-12 04:28 . 2010-06-12 04:28 -------- d-----w- c:\documents and settings\dan\Application Data\mjusbsp
2010-06-12 04:28 . 2010-06-12 04:28 -------- d-----w- c:\documents and settings\dan\Application Data\Ahead
2010-06-12 04:25 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2010-06-12 04:25 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Nikon
2010-06-12 04:25 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Memeo
2010-06-12 04:25 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-12 04:25 . 2010-06-12 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2010-06-12 04:06 . 2010-01-27 19:06 -------- d-----w- c:\program files\MSBuild
2010-06-12 04:06 . 2010-06-12 04:06 -------- d-----w- c:\program files\Microsoft.NET
2010-06-12 04:05 . 2010-06-12 04:05 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-06-12 03:58 . 2010-06-12 03:58 -------- d-----w- c:\program files\Alwil Software
2010-06-12 03:30 . 2010-06-12 03:30 0 ----a-w- c:\windows\nsreg.dat
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-18 23:35 . 2010-05-18 23:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 23:35 . 2010-05-18 23:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-08 00:29 . 2010-05-08 00:29 36864 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2010-05-08 00:29 . 2010-05-08 00:29 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
2010-05-08 00:29 . 2010-05-08 00:29 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2002-09-11 14:26 . 2006-07-31 02:51 63730 ----a-w- c:\program files\viewsonicinstruct_xp.pdf
2010-06-15 20:37 . 2010-06-15 20:37 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"GFI Backup 2009 - Home Edition"="c:\progra~1\GFI\GFIBAC~1\GFIAgent.exe" [2010-04-27 2185000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-17 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-17 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-17 144920]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-04 103720]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"RTHDCPL"="RTHDCPL.EXE" [2010-02-22 18791456]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"LTCM Client"="c:\program files\LTCM Client\ltcmClient.exe" [2009-03-02 1583808]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0360.0\mswinext.exe" [2009-11-18 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-15 30192]
"VX1000"="c:\windows\vVX1000.exe" [2009-06-27 757248]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

c:\documents and settings\dan\Start Menu\Programs\Startup\
MP3 Rocket (Minimized).lnk - c:\program files\MP3 Rocket\MP3Rocket.exe [2010-1-28 174080]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [1/27/2010 10:01 AM 51840]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [1/27/2010 10:01 AM 143256]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8/4/2010 7:10 AM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/4/2010 7:10 AM 17744]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [1/27/2010 10:01 AM 24971]
S0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [1/27/2010 10:01 AM 85888]
S0 mv614x;mv614x;c:\windows\system32\drivers\mv614x.sys [1/27/2010 10:01 AM 61184]
S0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [1/27/2010 10:01 AM 89610]
S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [1/27/2010 10:01 AM 45568]
S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [1/27/2010 10:01 AM 77056]
S2 gupdate1cb0dcdc4e4ad2e;Google Update Service (gupdate1cb0dcdc4e4ad2e);c:\program files\Google\Update\GoogleUpdate.exe [6/16/2010 8:32 PM 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys [5/7/2010 5:29 PM 1691480]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys --> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/15/2010 1:37 PM 30192]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys --> c:\windows\system32\DRIVERS\ivusb.sys [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]

--- Other Services/Drivers In Memory ---

*Deregistered* - ekpiolpi
*Deregistered* - quepv
.
Contents of the 'Scheduled Tasks' folder

2010-08-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

2010-08-04 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-17 03:32]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://www.msn.ca/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\dan\Application Data\Mozilla\Firefox\Profiles\0kxie2lv.default\
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-04 16:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ekpiolpi]

--

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\quepv]

.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3880835809-259470027-1274852034-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@SACL=

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3792)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\program files\Java\jre6\bin\javaw.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-08-04 16:49:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-04 23:49

Pre-Run: 457,201,659,904 bytes free
Post-Run: 457,690,255,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 274D60185FD04520340E16F78AF30FEF

Any and all help really appreciate

Attached Files



BC AdBot (Login to Remove)

 


#2 killbugsdead

killbugsdead
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:35 PM

Posted 13 August 2010 - 07:32 AM

Gentlemen\ladies. I booted into dos with BartPE and deleted the two files. Alll scanners come up with no more rootkit. i am not sure if that will solve the whole problem or if it will reapear but i had to dekiver the machine back to client. thank you for your help.

#3 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:35 AM

Posted 13 August 2010 - 04:28 PM

As this issues appears to be resolved I am closing the topic. Please send me a PM if you would like it reopened.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users